# auth.md - Access guidance for Tokenizart and Atelier

Tokenizart's public website and Atelier's public resource documents can be read without signing in. Public resources describe capabilities; they do not grant access to a user's account.

## Public assistant

[Companion](https://companion.tokenizart.info/companion) provides public information and guidance. It is a separate application linked from Tokenizart. Public information is not a view of an authenticated Atelier dashboard.

## Authenticated assistant

[Copilot](https://companion.tokenizart.info/internal/level4-copilot) uses a protected sign-in flow. Access is subject to the pilot's permitted accounts. A user must also connect their own Atelier account through the application before private account information can be read.

A connection is temporary and can expire or be revoked. Signing in to Copilot alone does not establish access to Atelier. A hyperlink to either application does not delegate permissions.

## User actions

Reading documentation and receiving guidance do not authorize transactions. Mint, Certify and transfers retain the platform's transaction checks and the user's final wallet signature. Never send a wallet private key, password or sign-in code to an assistant.

## Machine clients

This document is explanatory access guidance, not an OAuth discovery document or a promise that a public MCP endpoint is available. Consult each tool's published instructions and verified capabilities. Do not reuse browser sessions or infer permission from a public URL.
